{"id":54515,"date":"2025-10-02T08:01:25","date_gmt":"2025-10-02T12:01:25","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=54515"},"modified":"2025-10-02T08:01:25","modified_gmt":"2025-10-02T12:01:25","slug":"whatsapp-phishing-vote","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/whatsapp-phishing-vote\/54515\/","title":{"rendered":"Phishing via WhatsApp under the guise of online voting"},"content":{"rendered":"<p>\u201cHi! My niece is in a contest! Can you vote for her? It means the world to her\u201d. Messages like this are common on WhatsApp \u2014 both in groups and private chats. Many people who aren\u2019t security-savvy will, without a second thought, click to help someone they don\u2019t actually know \u2014 and end up losing their account. In a recent investigation we found a new phishing campaign that has already hit WhatsApp users worldwide.<\/p>\n<p>Today we\u2019ll explain how the attack works, the potential consequences for victims, and how to avoid falling for it.<\/p>\n<h2>How the attack works<\/h2>\n<p>Cybercriminals first prepare for the attack by creating convincing phishing pages purportedly hosting legitimate voting polls \u2014 in the example below for young gymnasts, though the scenario can be easily changed. The pages look genuine: they include photos of real participants, <em>Vote<\/em> buttons and counters showing how many people have voted. Likely using AI and <a href=\"https:\/\/securelist.com\/phishing-kit-market-whats-inside-off-the-shelf-phishing-packages\/106149\/\" target=\"_blank\" rel=\"noopener\">phishing-kits<\/a>, the attackers easily produce multiple language versions of the same site \u2014 we found the identical poll in English, Spanish, German, Turkish, Danish, Bulgarian, and other languages.<\/p>\n<p><strong>Stage One: The Hook. <\/strong>On social networks, in messengers, or by email, the scammers use social engineering to direct you to a fake voting site. The pretext can be very believable, and the message may come from a friend or relative whose account has already been compromised. The request is usually personalized \u2014 in the first message the fraudster posing as your acquaintance asks you to vote for a certain contestant because they\u2019re their charge, friend or relative.<\/p>\n<div id=\"attachment_54519\" style=\"width: 1016px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02074925\/whatsapp-phishing-vote-1-1.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-54519\" class=\"size-full wp-image-54519\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02074925\/whatsapp-phishing-vote-1-1.jpg\" alt=\"First you're lured to a fake voting page\" width=\"1006\" height=\"846\"><\/a><p id=\"caption-attachment-54519\" class=\"wp-caption-text\">First you\u2019re lured to a fake voting page<\/p><\/div>\n<p><strong>Stage Two: The Trap.<\/strong> When you click <em>Vote<\/em>, you\u2019re taken to a page that asks you to quickly authenticate via WhatsApp. All you need do is enter the phone number linked to your messenger.<\/p>\n<div id=\"attachment_54522\" style=\"width: 1386px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075121\/whatsapp-phishing-vote-2-1.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-54522\" class=\"size-full wp-image-54522\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075121\/whatsapp-phishing-vote-2-1.jpg\" alt='Next they ask for your phone number associated with WhatsApp. The scammers even pretend to care about your data and \"your valuable time\"' width=\"1376\" height=\"643\"><\/a><p id=\"caption-attachment-54522\" class=\"wp-caption-text\">Next they ask for your phone number associated with WhatsApp. The scammers even pretend to care about your data and \u201cyour valuable time\u201d<\/p><\/div>\n<p><strong>Stage Three: The Heist<\/strong>. The attackers exploit the one-time code login feature in WhatsApp Web. They enter the phone number you provided, and WhatsApp generates an eight-character single-use verification code. The attackers immediately display that code on the fake site with instructions: open WhatsApp, go to \u201cConnected devices\u201d (never mind that it\u2019s actually \u201cLinked devices\u201d in WhatsApp), and enter the code. For convenience, there\u2019s even a button to copy the code to the clipboard.<\/p>\n<div id=\"attachment_54524\" style=\"width: 1378px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075438\/whatsapp-phishing-vote-3.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-54524\" class=\"size-full wp-image-54524\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075438\/whatsapp-phishing-vote-3.jpg\" alt='For \"fast and easy authorization\" (read: WhatsApp account takeover) you only need enter the code shown on the site' width=\"1368\" height=\"628\"><\/a><p id=\"caption-attachment-54524\" class=\"wp-caption-text\">For \u201cfast and easy authorization\u201d (read: WhatsApp account takeover) you only need enter the code shown on the site<\/p><\/div>\n<p>At the same time, WhatsApp on your phone shows a prompt to link a new device by entering the code. Clicking that opens a warning that someone is trying to connect to your account, and a field to enter the code.<\/p>\n<p>Unfortunately, in their uncontrollable desire to help a complete stranger in the contest, many users don\u2019t carefully read WhatsApp\u2019s warning. They think, \u201cSomeone wants to link to my account? That\u2019s so I can vote \u2014 looks fine to me\u201d When the careless victim types the code into the app on their phone, the web session initiated by the attackers is activated.<\/p>\n<div id=\"attachment_54525\" style=\"width: 1320px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075629\/whatsapp-phishing-vote-4.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-54525\" class=\"size-full wp-image-54525\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2025\/10\/02075629\/whatsapp-phishing-vote-4.png\" alt=\"WhatsApp warns you that someone is trying to link to your account, but many users don't read the warning, and enter the verification code anyway\" width=\"1310\" height=\"1274\"><\/a><p id=\"caption-attachment-54525\" class=\"wp-caption-text\">WhatsApp warns you that someone is trying to link to your account, but many users don\u2019t read the warning, and enter the verification code anyway<\/p><\/div>\n<p>If you enter that code, the attackers gain full access to your WhatsApp, as if you had logged in yourself \u2014 for example, from a computer alongside your phone. The attackers can view all your contacts, read conversations, send and delete messages in your name, and even take full control of the account. That opens up further possibilities for fraud: somehow extracting money from your contacts using your identity, or using your account to spread the same phishing link that trapped you.<\/p>\n<h2>What to do if you think you\u2019ve been hacked<\/h2>\n<p>If you suspect you\u2019ve fallen for the scam and given attackers access to your WhatsApp account, the first thing to do is open the WhatsApp settings on your smartphone and go to <em>Linked devices<\/em>. There you\u2019ll see all devices currently logged into your account. If you notice any unfamiliar devices or browsers, click on them to disconnect them from your account. Do this quickly \u2014 before the criminals can fully take over your account.<\/p>\n<p>We\u2019ve prepared a <a href=\"https:\/\/www.kaspersky.com\/blog\/whatsapp-account-hacked\/53069\/\" target=\"_blank\" rel=\"noopener nofollow\">detailed guide<\/a> for such cases: it explains eight signs your WhatsApp account may be hacked, and provides step-by-step instructions on how to regain access even in difficult situations. We also have a <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-account-hacked\/52775\/\" target=\"_blank\" rel=\"noopener nofollow\">similar guide for Telegram users<\/a>.<\/p>\n<h2>How to prevent your WhatsApp account from being hacked<\/h2>\n<ul>\n<li><strong>Never take part in dubious contests or votes<\/strong> \u2014 especially if they require messenger authentication. Legitimate polls don\u2019t ask for access to your personal accounts.<\/li>\n<li><strong>Don\u2019t click suspicious links<\/strong> in messages \u2014 even if they seem to come from friends or relatives. Their accounts may have been hacked.<\/li>\n<li><strong>Never enter personal data on unfamiliar websites<\/strong> \u2014 especially those reached via messages or social media links. Always check the URL carefully.<\/li>\n<li><strong>Don\u2019t ignore browser warnings<\/strong> about unsafe sites, and use <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Premium<\/a>\u00a0on all your devices (both smartphones and computers). Our protection scans links and webpages, blocks phishing and malicious resources, and works in all popular mobile and desktop browsers.<\/li>\n<li><strong>Enable two-factor verification<\/strong> in your WhatsApp settings. This makes a six-digit PIN code necessary to log in on a new device, making attackers\u2019 job harder even if your number is compromised. However, this doesn\u2019t protect against the attack described above \u2014 the one-time code shown to you is, in WhatsApp\u2019s view, already the \u201csecond factor\u201d. That\u2019s why the PIN isn\u2019t requested during this login method.<\/li>\n<li><strong>Use <\/strong><a href=\"https:\/\/www.kaspersky.com\/blog\/full-guide-to-passkeys-in-2025-part-1\/53688\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>passkeys<\/strong><\/a> instead of traditional passwords wherever possible. WhatsApp already supports passkeys for account verification.<\/li>\n<li><strong>Protect mobile devices from phishing<\/strong> \u2014 these are the main targets of messenger attacks. <a href=\"https:\/\/www.kaspersky.com\/blog\/notification-listener-in-kaspersky-for-android\/54466\/\" target=\"_blank\" rel=\"noopener nofollow\">Three-level protection technology<\/a> detects malicious links and blocks dangerous websites. At the first level, <strong>Notification Protection<\/strong> detects and automatically removes malicious links from app notifications, leaving only safe text. Next, <strong>Safe Messaging<\/strong> blocks harmful links in SMSs and messenger messages (WhatsApp, Viber, Telegram) before the user clicks them. Finally, <strong>Safe Browsing<\/strong> blocks malicious URLs in popular mobile browsers.<\/li>\n<li><strong>Configure privacy and security on both your smartphone and computer with <a href=\"https:\/\/privacy.kaspersky.com\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=gl_kd-banner_ap0072&amp;utm_content=banner&amp;utm_term=gl_kdaily_organic_hwzuab72aq5ynvk\" target=\"_blank\" rel=\"noopener\">Privacy Checker<\/a><\/strong>\u00a0\u2014 Kaspersky\u2019s free service that gives detailed guides for privacy settings in many popular apps, services, and operating systems.<\/li>\n<li><strong>Set up WhatsApp and Telegram<\/strong> accounts for maximum protection against hijacking <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-prevent-whatsapp-telegram-account-hijacking-and-quishing\/53012\/\" target=\"_blank\" rel=\"noopener nofollow\">using our step-by-step guide<\/a>.<\/li>\n<li><strong>Regularly check the list of connected devices<\/strong> in messengers\u2019 settings. Both WhatsApp and Telegram have sections showing all active sessions, and you can disconnect suspicious ones. In Telegram, you can even enable automatic termination of inactive sessions.<\/li>\n<li><strong>Only use official versions of messengers<\/strong> downloaded from official app stores (such as Google Play, App Store, or Galaxy Store). Modified versions <a href=\"https:\/\/www.kaspersky.com\/blog\/whatsapp-mods-canesspy\/49656\/\" target=\"_blank\" rel=\"noopener nofollow\">can contain malware<\/a>.<\/li>\n<li><strong>Be extra cautious with desktop versions of messengers<\/strong> \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/dangers-of-desktop-messengers\/47453\/\" target=\"_blank\" rel=\"noopener nofollow\">especially on work computers<\/a>.<\/li>\n<\/ul>\n<blockquote><p>How else do attackers target messengers, and how to counter them?<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-prevent-whatsapp-telegram-account-hijacking-and-quishing\/53012\/\" target=\"_blank\" rel=\"noopener nofollow\">How to protect WhatsApp and Telegram against hijacking in 2025<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/54090\/\" target=\"_blank\" rel=\"noopener nofollow\">Telegram scams with bots, gifts, and crypto<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-spot-and-prevent-boss-scams\/50861\/\" target=\"_blank\" rel=\"noopener nofollow\">Is it the boss \u2014 or is it a fraudster? <\/a><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-spot-and-prevent-boss-scams\/50861\/\" target=\"_blank\" rel=\"noopener nofollow\">Scams disguised as urgent orders from top brass<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-signal-malware-in-google-play\/48937\/\" target=\"_blank\" rel=\"noopener nofollow\">Spyware messengers on Google Play<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/what-makes-a-messenger-secure\/48671\/\" target=\"_blank\" rel=\"noopener nofollow\">What makes a messaging app secure?<\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>We discovered a new wave of attacks on WhatsApp users in which attackers steal victims&#8217; accounts using fake voting pages and social engineering on social networks.<\/p>\n","protected":false},"author":2710,"featured_media":54508,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[607,76,43,726,4247,1891,546],"class_list":{"0":"post-54515","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-messengers","9":"tag-phishing","10":"tag-privacy","11":"tag-scam","12":"tag-social-networks","13":"tag-voting","14":"tag-whatsapp"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/whatsapp-phishing-vote\/54515\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/whatsapp-phishing-vote\/29691\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/whatsapp-phishing-vote\/24762\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/whatsapp-phishing-vote\/12924\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/whatsapp-phishing-vote\/29579\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/whatsapp-phishing-vote\/28626\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/whatsapp-phishing-vote\/31507\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/whatsapp-phishing-vote\/30174\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/whatsapp-phishing-vote\/40606\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/whatsapp-phishing-vote\/13866\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/whatsapp-phishing-vote\/23266\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/whatsapp-phishing-vote\/24361\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/whatsapp-phishing-vote\/32775\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/whatsapp-phishing-vote\/29788\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/whatsapp-phishing-vote\/35523\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/whatsapp-phishing-vote\/35147\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/messengers\/","name":"messengers"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/54515","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2710"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=54515"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/54515\/revisions"}],"predecessor-version":[{"id":54518,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/54515\/revisions\/54518"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/54508"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=54515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=54515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=54515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}